PT-2017-16919 · F5 · F5 Big-Ip Pem+1

Publicado

2017-10-27

·

Atualizado

2019-10-03

·

CVE-2017-6160

CVSS v3.1

5.9

Média

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions F5 BIG-IP AAM and PEM software versions 11.4.1 through 11.5.4 F5 BIG-IP AAM and PEM software versions 11.6.0 through 11.6.1 F5 BIG-IP AAM and PEM software versions 12.0.0 through 12.1.1
Description A remote attacker may create maliciously crafted HTTP requests to cause the Traffic Management Microkernel (TMM) to restart and temporarily fail to process traffic. This issue is exposed on virtual servers using a Policy Enforcement profile or a Web Acceleration profile. Systems without the BIG-IP AAM or PEM module provisioned are not vulnerable.
Recommendations For versions 11.4.1 through 11.5.4, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available. For versions 11.6.0 through 11.6.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available. For versions 12.0.0 through 12.1.1, consider disabling the Policy Enforcement profile or Web Acceleration profile as a temporary workaround until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-6160

Produtos afetados

F5 Big-Ip Apm
F5 Big-Ip Pem